<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/204327#M253</link>
    <description>&lt;P&gt;Hi Warby,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The subnet requirements for VM series as mentioned below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;CIDR block 192.168.0.0/16, and allocates five subnets (192.168.1.0/24 - 192.168.5.0/24) for deploying the Azure Application Gateway, the VM-Series firewalls, the Azure load balancer and the web servers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it a mandate to have 19.168.x.x/24 (subnet ./24) or we can use (/30) subnet as it will consume 1 IP for external NIC, internal nic, management nic?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Mar 2018 14:28:24 GMT</pubDate>
    <dc:creator>sougata</dc:creator>
    <dc:date>2018-03-08T14:28:24Z</dc:date>
    <item>
      <title>Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/171006#M98</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to Paloalto and have some queries with regards to deployment of Paloalto on VM series Firewall on Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/about-the-vm-series-firewall-in-azure" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/about-the-vm-series-firewall-in-azure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon search we found&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; The VM-Series firewall in Azure does not support native VM Monitoring capabilities for virtual machines that are hosted in Azure.&lt;/P&gt;&lt;P&gt;&amp;gt; VM-Series high availability configuration is not supported to avoid downtime during plannned/unplanned maintainance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The way of solution is to have Azure application gateway in front of the VM series firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/deploy-the-vm-series-and-azure-application-gateway-template#_69395" target="_blank" rel="noopener noreferrer"&gt;https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/deploy-the-vm-series-and-azure-application-gateway-template#_69395&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Queries that i had in mind:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. If HA cannot be configured between the VM's( that might be 2 or 3) that are deployed in the VM Series firewall, how the configurations gets replicated between the firewall running on separate VM's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. How is the session state maintained when a connection is initiated from App gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. We want user defined routing between subnets and next hop should pass through Paloalto firewall (internal subnet- Trusted). What is the next hop address that we put if each VM in the VM series firewall with Paloalto holds a different IP address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to the subnet example in the link below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="acChatHistory acChatHistoryBlack"&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/vm-series-and-azure-application-gateway-template#_64281" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/virtualization/virtualization/set-up-the-vm-series-firewall-in-azure/vm-series-and-azure-application-gateway-template#_64281&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 12:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/171006#M98</guid>
      <dc:creator>sougata</dc:creator>
      <dc:date>2017-08-10T12:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/171154#M99</link>
      <description>&lt;P&gt;There are several options for high availability in Azure. &amp;nbsp;Check out our cloud integration page and expand the Azure section for some examples:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Public-Cloud-Integration/ct-p/Cloud_Templates" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Public-Cloud-Integration/ct-p/Cloud_Templates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall configurations can by synchronized accross multiple firewalls using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;our Azure bootstrapping feature with a common config XML&lt;/LI&gt;&lt;LI&gt;Panorama&lt;/LI&gt;&lt;LI&gt;Ansible&lt;/LI&gt;&lt;LI&gt;Our API&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;We don't maintain session state in the public cloud as most cloud applications are designed to handle state and the infrastructure is stateless. &amp;nbsp;This is true of other services as well like load balancers in Azure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want to have redundant firewalls for security between subnets, you will need to either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;point a UDR at a primary interface and use an Azure function to move the UDR in the case of a failure&lt;/LI&gt;&lt;LI&gt;front the redundant firewalls with an Azure LB and point a UDR to the LB&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Follow the link above for examples.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 23:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/171154#M99</guid>
      <dc:creator>Warby</dc:creator>
      <dc:date>2017-08-10T23:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/171197#M100</link>
      <description>&lt;P&gt;Hi Warby, thanks for the prompt response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;======================================&lt;/P&gt;&lt;P&gt;Firewall configurations can by synchronized accross multiple firewalls using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;our Azure bootstrapping feature with a common config XML&lt;/LI&gt;&lt;LI&gt;Panorama&lt;/LI&gt;&lt;LI&gt;Ansible&lt;/LI&gt;&lt;LI&gt;Our API&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;======================================&lt;BR /&gt;&lt;BR /&gt;I do need some clarity on the above. Following is what I have understood:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We can achieve the config sync during startup with the bootstrapping feature.&lt;/LI&gt;&lt;LI&gt;We configure the firewalls with Panorama&lt;/LI&gt;&lt;LI&gt;I guess Ansible along with API's would be used to sync the configuration while firewalls are in operation.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is my understanding correct. Also, please share any configuration guide for the same, if available.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 05:29:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/171197#M100</guid>
      <dc:creator>sougata</dc:creator>
      <dc:date>2017-08-11T05:29:30Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/173315#M103</link>
      <description>&lt;P&gt;Either&amp;nbsp;Ansible (using our API) or Panorama can keep the configs in synch post deployment (while the firewall is running.)&lt;/P&gt;</description>
      <pubDate>Sat, 26 Aug 2017 22:06:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/173315#M103</guid>
      <dc:creator>Warby</dc:creator>
      <dc:date>2017-08-26T22:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/204327#M253</link>
      <description>&lt;P&gt;Hi Warby,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The subnet requirements for VM series as mentioned below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;CIDR block 192.168.0.0/16, and allocates five subnets (192.168.1.0/24 - 192.168.5.0/24) for deploying the Azure Application Gateway, the VM-Series firewalls, the Azure load balancer and the web servers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Question:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it a mandate to have 19.168.x.x/24 (subnet ./24) or we can use (/30) subnet as it will consume 1 IP for external NIC, internal nic, management nic?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 14:28:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/204327#M253</guid>
      <dc:creator>sougata</dc:creator>
      <dc:date>2018-03-08T14:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/204336#M254</link>
      <description>&lt;P&gt;Azure reserves the first 3 IP addresses for Azure services and /29 is the smallest allowed mask leaving only 3 usable in the subnet, 2 of which will be assigned to the firewalls.&amp;nbsp; There are times where you may wish to bring up a new pair of firewalls in parallel and you will not have enough IPs to do so.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq" target="_blank"&gt;https://docs.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 15:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/204336#M254</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2018-03-08T15:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/214625#M305</link>
      <description>&lt;P&gt;We actually used 2 pairs of firewalls for our Azure deployment. One pair is North-South and the other is East-West monitoring.&amp;nbsp; We used Standard SKU load balancers to make a "HA" solution.&amp;nbsp; It is important to note that you have to have a LB on the trust and untrus side for this configuration.&amp;nbsp; With the Standard SKU vs Basic SKU, you are able to select "HA Ports" meaning you don't have to specifcally call out the ports for the load balancers to forward traffic to the Firewalls.&amp;nbsp; For routing, all on-prem traffic went to one pair of firewalls and Internet went to the other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our UDR looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trust vNets:&lt;/P&gt;&lt;P&gt;From Any to 172.x.x.x/x goes to EW Trusted Load balancer (one for each vNet)&lt;/P&gt;&lt;P&gt;0.0.0.0/0 goes to NS Trusted Load balancer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Untrust vNet:&lt;/P&gt;&lt;P&gt;From 172.x.x.x/x&amp;nbsp; To 192.168.x.x/x goes to EW Untrust Load Balancer&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 20:53:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/214625#M305</guid>
      <dc:creator>ebrookman</dc:creator>
      <dc:date>2018-05-17T20:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219175#M364</link>
      <description>&lt;P&gt;Hi ebrookman,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are you using the basic sku load balancer to handle east-west monitoring?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you dont mind how did you configure the "basic sku" load balancer to handle all the ports that might be required for east-west monitoring? Say all the dynamic high level ports for instance?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219175#M364</guid>
      <dc:creator>RREALICA</dc:creator>
      <dc:date>2018-06-25T20:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219176#M365</link>
      <description>&lt;P&gt;We started using the basic load balancers, but found out that you would have to declare all ports that will be used.&amp;nbsp; By using the Standard Load Balancers, you can use what they call "HA Ports" which is just dynamic port mapping.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 20:37:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219176#M365</guid>
      <dc:creator>ebrookman</dc:creator>
      <dc:date>2018-06-25T20:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219200#M366</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In our instance the, since we are in Azure Gov, the standard load balancer is not available as of yet so we have to lived with the limitations of the basic load balancers for the time being. I'm wondering how other users handles the requirements for example for Active Directory dynamic ports like a range of 49152 - 65535 TCP? How do you define that in the basic load balancer? Is there a need to?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 00:32:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219200#M366</guid>
      <dc:creator>RREALICA</dc:creator>
      <dc:date>2018-06-26T00:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219203#M367</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;How did you able to set backend pool on Azure Gov? I heard that there is no availability set on Azure Gov.&lt;/P&gt;&lt;P&gt;I build a basic LB but not able to select both firewalls since I'm not able to build both firewalls on an availabilty set.&lt;/P&gt;&lt;P&gt;Then I have same questions, how to set a rule with dynamic ports on basic LB.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 01:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/219203#M367</guid>
      <dc:creator>hsong</dc:creator>
      <dc:date>2018-06-26T01:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Networking-UDRs-in-Azure-Inserting-the-VM-Series-into-an-Azure</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/223704#M373</link>
      <description>&lt;P&gt;On the dynamic ports, you have to use the standard sku LB.&amp;nbsp; The firewalls are set up in the backend pool, but aren't in an av set with each other.&amp;nbsp; As the last post here states, there are a lot of restrictions based on Azure not PA.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jul 2018 17:47:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/networking-udrs-in-azure-inserting-the-vm-series-into-an-azure/m-p/223704#M373</guid>
      <dc:creator>ebrookman</dc:creator>
      <dc:date>2018-07-26T17:47:21Z</dc:date>
    </item>
  </channel>
</rss>

